> I think my keyword here was `something like'.  /tmp would be
   > hardcoded so such things cannot happen, and not links to be
   > followed, etc etc etc.

   Probably not going to happen. I read somewhere that if users are
   allowed to reap /tmp anytime at will, a malicious user can exploit
   some race condition in tmp file creation to do privilege
   escalation.

Could you dig up the article?  I can't see any reasons why it wouldn't
be utterly trivial to make such a program totally abuse safe.


_______________________________________________
Gnu-arch-users mailing list
Gnu-arch-users@gnu.org
http://lists.gnu.org/mailman/listinfo/gnu-arch-users

GNU arch home page:
http://savannah.gnu.org/projects/gnu-arch/

Reply via email to